1. CryptoExperts is like a European version of Cryptography Research; it’s people from Gemalto, INRIA, Antoine Joux, Lous Goubin, their grad students, &c. They’re not randos.

2. Their paper doesn’t claim anything is wrong with 25519. They’re just proposing a random Edwards curve alternative to 25519, with a cute trick to generate credible random parameters. Their paper rejects the Brainpool-y parameters-from-math-constants approach, citing Bernstein’s BADA55 argument, in favor of pure random parameters. 

